Outer Rim Archives
Archives · 2023 · 20230134781

Application (pre-grant publication)

PRIVACY PROTECTION FOR ENTERPRISE SYSTEMS

Number
20230134781
Published
2023-05-04
Filed
2021-11-03
Assignee
Disney Enterprises, Inc.
Inventors
Senerth; Mark F. et al.
CPC
G06F21/6227; H04L9/0643; G06F21/6254; G06F21/6245; H04L9/0819; H04L9/0894
Verdict
Set aside enterprise privacy/security, IT
Source
Google Patents · FreePatentsOnline

Abstract

Techniques for electronic privacy protection are disclosed. A first data record is received, including one or more sensitive data fields and one or more non-sensitive data fields. One or more encrypted data fields are generated by encrypting the one or more sensitive data fields using an encryption key. One or more hashed data fields are generated by hashing the one or more sensitive data fields using a hash function. A first mapping is stored, associating at least a portion of the first data record with the encryption key. A second data record is stored, including the one or more non-sensitive data fields, the one or more encrypted data fields, and the one or more hashed data fields.

Background

BACKGROUND

Protecting consumer privacy is a challenging problem. Enterprise privacy protection should both protect sensitive data so that it cannot be tied back to a particular individual, and reduce, to the extent possible, the accessibility of sensitive data within the enterprise platform. This can help reduce data spill and increase protection for sensitive data. An undesirable approach to privacy protection can, however, cause significant problems for an organization. For example, it could create excessive organizational complexity, increasing the probability of costly misconfigurations. An undesirable approach can also have implications on the everyday operational compute costs. A privacy policy that is too restrictive also results in stunting creativity. An enterprise privacy solution should, instead, protect consumer privacy, while avoiding causing problems for the larger organization.

Claims

1. A method, comprising: receiving a first data record comprising one or more sensitive data fields and one or more non-sensitive data fields; generating one or more encrypted data fields by encrypting the one or more sensitive data fields using an encryption key; generating one or more hashed data fields by hashing the one or more sensitive data fields using a hash function; storing a first mapping associating at least a portion of the first data record with the encryption key; and storing a second data record comprising the one or more non-sensitive data fields, the one or more encrypted data fields, and the one or more hashed data fields. || 12. A non-transitory computer-readable medium containing computer program code that, when executed by operation of one or more computer processors, performs an operation comprising: receiving a first data record comprising one or more sensitive data fields and one or more non-sensitive data fields; generating one or more encrypted data fields by encrypting the one or more sensitive data fields using an encryption key; generating one or more hashed data fields by hashing the one or more sensitive data fields using a hash function; storing a first mapping associating at least a portion of the first data record with the encryption key; and storing a second data record comprising the one or more non-sensitive data fields, the one or more encrypted data fields, and the one or more hashed data fields. || 17. A system, comprising: a computer processor; and a memory having instructions stored thereon which, when executed on the computer processor, performs an operation comprising: receiving a first data record comprising one or more sensitive data fields and one or more non-sensitive data fields; generating one or more encrypted data fields by encrypting the one or more sensitive data fields using an encryption key; generating one or more hashed data fields by hashing the one or more sensitive data fields using a hash function; storing a first mapping associating at least a portion of the first data record with the encryption key; and storing a second data record comprising the one or more non-sensitive data fields, the one or more encrypted data fields, and the one or more hashed data fields.